Based on the original article by Martin Weber, data centre consultant at Prior1
KRUSE Sicherheitssysteme has received VdS approval for an emergency key depot that replaces the separate mechanical access key with a digitally generated one-time code. The system is designed to give authorised emergency personnel faster access to protected premises while combining physical security, electronic monitoring and digital credential management. The approval process also included a cybersecurity assessment of the associated web application. Emergency key depots are used to make keys to protected buildings available to authorised responders without giving unrestricted access to the property. KRUSE has now added a digital access mechanism to this concept. Instead of carrying an additional mechanical key for the depot itself, responders receive a one-time code generated by a control centre. The credential can be transmitted by radio communication or via an app and is valid for a single opening only. If a code is lost, entered incorrectly or otherwise needs to be replaced, a new credential can be generated and the previous one invalidated. This removes the risks associated with losing or copying a physical access key. At the same time, opening events are logged electronically, while the depot and the keys stored inside it can be continuously monitored.
Digital integration into control-room workflows
The concept is also intended to simplify integration into professional security and emergency-response operations. One-time codes can be requested through a secure digital interface from customer-side applications, including control-room software. This allows access authorisation to become part of an existing operational workflow rather than a separate manual process. It also makes the system easier to scale across larger numbers of sites or response teams. VdS awarded the system approval number G126007 following testing based on its current requirements for key depots. For international readers, VdS Schadenverhütung is a Germany-based independent testing and certification organisation widely used in the DACH security and fire-protection markets. Its approvals are frequently referenced by insurers, installers, planners and operators when assessing the technical reliability and security level of products and systems. According to Günter Grundmann, Deputy Head of Security & Geo at VdS Schadenverhütung, the approval confirms that the solution meets VdS requirements not only for technical reliability and resistance to tampering, but also for the underlying processes and digital management of the access codes.
Cybersecurity becomes part of physical access control
The assessment went beyond the physical depot itself. In the VdS security laboratories, the operating electronics were examined for reliability, usability and resistance to manipulation. The web application used to administer and generate the one-time codes was also evaluated from a cybersecurity perspective. The assessment included the availability and consistency of the application, secure authorisation procedures and encryption of data transmissions. A particularly relevant feature is the separation of code generation and verification. The one-time credentials are generated and validated independently within the key depot and the web application. As a result, the depot does not require a permanent connection to the web application or the internet in order to accept a valid code. For critical access processes, this architecture reduces dependence on continuous connectivity and helps maintain availability even when network access is disrupted. Philipp Kruse, Managing Director of KRUSE Sicherheitssysteme, says the approval provides operators and control centres with additional security and transparency while allowing the access-code process to be integrated directly into existing applications. The development also reflects a broader trend in physical security. Access to protected assets is increasingly no longer secured by a single mechanical credential alone. Instead, the security level depends on the complete chain of authorisation, transmission, verification, logging and system resilience. For emergency access applications in particular, that combination is becoming critical: the system has to provide rapid entry when required while ensuring that every credential remains temporary, traceable and protected against unauthorised use.




